https://github.com/openclaw/openclaw
· scanned 2026-06-05 04:24 UTC (4 hours, 46 minutes ago)
· 10 languages
5760 findings (222 legacy + 5538 scanner) 11/13 scanners ran 89th percentile · Typescript · huge (>500K LoC) Scanner says 56 (higher by 36)
Last scanned 4 hours, 46 minutes ago · v3 · 2068 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
91.0 | 0.15 | 13.65 |
code_quality |
65.0 | 0.10 | 6.50 |
| Overall | 1.00 | 91.9 |
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
skills/skill-creator/scripts/package_skill.py:114
skills/skill-creator/scripts/init_skill.py:300
skills/skill-creator/scripts/init_skill.py:292
skills/skill-creator/scripts/init_skill.py:280
skills/model-usage/scripts/model_usage.py:259
skills/model-usage/scripts/model_usage.py:91
.well-known/security.txt
index.html
src/commands/status.update.ts:1
src/commands/doctor-update.ts:1
src/agents/apply-patch-update.ts:1
extensions/matrix/src/migration-snapshot-backup.ts:1
src/cli/requirements-test-fixtures.ts:17
src/cli/requirements-test-fixtures.ts:7
.pre-commit-config.yaml:54
.pre-commit-config.yaml:39
.pre-commit-config.yaml:33
.pre-commit-config.yaml:24
.pre-commit-config.yaml:9
scripts/e2e/telegram-user-driver.py:513
This page is publicly accessible at:
https://repobility.com/scan/133fe0c7-218e-4742-847e-cbe2f5a1fb4f/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/133fe0c7-218e-4742-847e-cbe2f5a1fb4f/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.